3Com 7750 Series Switch User Manual


  Open as PDF
of 1177
 
3Com Switch 7750 Series
Command Reference Guide – AAA, RADIUS, HWTACACS, EAD
Chapter 1 AAA & RADIUS & HWTACACS
Configuration Commands
1-59
authorization: Specifies a shared key for the authorization server.
string: Shared key, a string of up to 16 characters.
Description
Use the key command to configure a shared key for HWTACACS authentication,
authorization or accounting server.
Use the undo key command to delete the configuration.
By default, no key is set for any HWTACACS server.
The TACACS client (on the switch) and the TACACS server use the MD5 algorithm to
encrypt the HWTACACS packets communicated between them. They authenticate
packets by using shared keys. Either of them receives and responds to the packet sent
from the other party only when their shared keys are the same. Therefore, the shared
key set on the switch and that on the TACACS server must be the same.
If the authentication/authorization server and the accounting server are different and
the shared key for the two servers are different, a shared key must be set for
authentication/authorization packets and accounting packets.
Related command: display hwtacacs.
Example
# Use hello as the shared key for TACACS accounting server.
<3Com> system-view
System View: return to User View with Ctrl+Z.
[3Com] hwtacacs scheme test1
[3Com-hwtacacs-test1] key accounting hello
1.3.7 nas-ip
Syntax
nas-ip ip-address
undo nas-ip
View
HWTACACS scheme view
Parameter
ip-address: Specified source IP address, in dotted decimal notation.